Blog

AI Tools & Client Data Security: What Firms Need to Know

Accounting firms using AI tools risk exposing client data under GLBA, IRS Publication 4557, and Section 7216. Learn what safe adoption looks like.

minute read

Last Updated July 28, 2026

Category Automation & AI

Share

AI Tools & Client Data Security: What Accounting Firms Need to Know

Key Takeaways

  • Consumer-tier AI tools are not covered by confidentiality agreements; data entered into them leaves your control.
  • The FTC Safeguards Rule, IRS Publication 4557, and IRC Section 7216 all apply to how AI tools handle client data.
  • Shadow AI, where staff use unsanctioned tools without firm approval, is a larger exposure than most firm leaders realize.
  • AI-generated output sent to a client without human review is a quality control failure, regardless of how it was produced.
  • Safe AI adoption starts with an acceptable use policy, sanctioned enterprise-tier tools, and updated vendor due diligence.

AI tools have moved from novelty to daily habit in accounting firms faster than almost any technology in memory.

Staff are using ChatGPT to draft client emails, Copilot to summarize workpapers, and AI notetakers to capture every word of client meetings.

The productivity gains are real. However, with AI adoption outpacing AI governance, there are some real risks around unintended consequences.

For firms handling tax and financial data, those risks carry regulatory weight that most general-purpose AI guidance fails to mention.

I would never argue against using AI. I will, however, always argue for an exercise in extreme caution.

Here’s what firm leaders need to understand about where the exposure actually is, and what to do about it.

The Core Problem: Client Data Leaving Your Control

Most of the risk of AI in an accounting firm reduces to a single question: where does the data go when someone hits Enter?

When a staff member pastes a client’s trial balance, a draft engagement letter, or the details of a messy shareholder dispute into a free consumer AI tool, that data leaves your environment and lands on someone else’s infrastructure, often under terms of service that permit the provider to retain it, review it, and in some cases use it to train future models.

Consumer-tier AI tools are generally not covered by any confidentiality agreement, business associate arrangement, or data processing addendum. The data is simply gone from your control.

For an accounting firm, this isn’t just a bad look. It intersects directly with your existing obligations:

FTC Safeguards Rule

The FTC Safeguards Rule (under GLBA) requires firms that prepare returns or provide financial services to maintain a written information security program with controls over how customer information is accessed and shared. An unmanaged flow of client data into consumer AI tools is, functionally, an uncontrolled disclosure channel your program doesn’t account for.

IRS Publication 4557

IRS Publication 4557 makes clear that tax professionals are responsible for safeguarding taxpayer data wherever it flows—including to third-party services. “An employee pasted it into a chatbot” is not a recognized exception.

IRC Section 7216

IRC Section 7216 imposes criminal penalties on tax return preparers who disclose or use tax return information without proper consent. Whether sending return data to an AI provider constitutes a disclosure requiring consent is exactly the kind of question you want your counsel answering before it happens, not after.

Professional confidentiality obligations

Professional confidentiality obligations under state accountancy rules and the AICPA Code of Professional Conduct don’t have an AI carve-out.

Many firms have already leaked client data this way and don’t know it, because nobody was looking.

Shadow AI in Accounting Firms: The Risks Hiding in Plain Sight

Firm leadership often believes AI usage is limited because the firm hasn’t formally adopted anything.

In practice, the opposite is true.

When there’s no sanctioned option, staff use unsanctioned ones: personal ChatGPT accounts, free browser extensions, and AI features embedded in tools they already use.

This “shadow AI” problem is worse than shadow IT of the past for two reasons:

  1. The barrier to entry is zero: no installation, no procurement, no IT ticket.
  2. The data shared is conversational and unstructured: This means your traditional controls (file transfer monitoring, USB restrictions) never see it.

A few patterns worth watching for specifically:

1. AI meeting notetakers and client call transcripts

AI meeting notetakers record and transcribe entire conversations, including the parts where clients discuss litigation exposure, personal financial distress, or M&A plans, and store those transcripts with a third party. Some auto-join every meeting on a calendar once installed.

2. Browser extensions with hidden AI features

Browser extensions with AI features can read the contents of every page a user views, including your tax software, client portal, and webmail.

3. AI embedded in tools you’ve already approved

Embedded AI in existing SaaS tools may be enabled by the vendor via an update, changing the tool’s data flow under different assumptions you already approved.

Why AI Hallucinations Are a Professional Liability Risk

Generative AI produces fluent, confident output that is sometimes wrong. It’s wrong in ways that are hard to spot precisely because it sounds authoritative.

In an accounting context, the failure modes are specific and consequential: fabricated citations to a nonexistent tax authority, a plausible but incorrect treatment of a transaction, or a summary that omits the one caveat that mattered.

You own the work product, regardless of who produced the first draft

The professional standards issue here is straightforward: the firm and the signing professional own the work product, regardless of what tools produced the first draft.

AI output sent to a client or returned without competent human review is a quality control failure.

Your review procedures need to treat AI-drafted content as unreviewed staff work, not as a finished product.

cta leading to safe gen AI usage policy ebook

New Cybersecurity Risks Created by AI Tools in Accounting Firms

Two risks are still underappreciated in most firms:

1. Prompt injection attacks

As firms adopt AI tools that can read documents, emails, and websites, attackers can embed hidden instructions inside that content—instructions the AI may follow.

A malicious payload buried in a PDF sent by a “prospective client” could attempt to manipulate an AI assistant into exfiltrating data or taking actions on the attacker’s behalf.

The more autonomy and data access an AI tool has, the more this matters.

2. AI-powered phishing and social engineering

The same tools that help your staff draft emails are helping criminals draft better phishing emails.

Voice cloning has made “the managing partner called and asked me to wire the funds” attacks dramatically more convincing.

Firms should assume that social engineering targeting their people is now higher quality, better personalized, and cheaper to produce at scale and adjust verification procedures (especially for payment changes and credential requests) accordingly.

CTA leading to security for accounting firm ebook

How to Safely Adopt AI in Your Accounting Firm

None of this argues for banning AI. Bans just drive usage further into the shadows.

It argues for giving your team a safe, sanctioned path and putting guardrails around it.

A practical starting point:

1. Write an AI acceptable use policy.

Define which tools are approved, what data categories may and may not be entered into them (client PII, taxpayer data, and confidential engagement information belong on the prohibited list for anything not under contract), and who approves new tools. Make it short enough that people actually read it.

2. Use enterprise-tier AI tools with data protections to match.

Business and enterprise tiers of major AI platforms typically offer contractual commitments that free tiers don’t: no training on your data, defined retention, admin controls, and audit logging.

Paying for the right tier is the difference between a managed vendor relationship and an uncontrolled disclosure.

3. Do vendor due diligence like you would for any provider touching client data.

  • Where is data stored and for how long?
  • Is it used for model training?
  • Can you get a data processing agreement?
  • Does the vendor hold SOC 2 or equivalent attestation?

If the answers aren’t available, that tells you something, too.

4. Update your written information security program.

Your FTC Safeguards Rule risk assessment should explicitly address AI tools as a data flow. If it was written before 2023, it almost certainly doesn’t.

AI Is Here—Is Your WISP Ready? →

5. Train your team on why the rules exist.

Staff paste client data into chatbots because it’s fast and they don’t perceive risk. Ten minutes explaining where the data goes — and what Section 7216 penalties look like — changes behavior more than a policy PDF ever will.

6. Require human review of AI output that touches client work.

Treat it as staff-prepared draft work subject to your normal review standards. Document that expectation.

7. Address consent where required.

Work with counsel on whether and when your engagement letters and Section 7216 consents need updating to reflect AI-assisted workflows.

8. Harden against AI-powered attacks.

Out-of-band verification for payment and banking changes, phishing-resistant multifactor authentication (MFA), and updated security awareness training that covers deepfakes and voice cloning.

What This Means for Your Firm

AI is going to be part of how accounting work gets done—that ship has sailed. Firms that use it well will have a real advantage.

But “using it well” means treating AI tools as what they are: third-party services processing your clients’ most sensitive information, subject to the same scrutiny, contracts, and controls you’d apply to any vendor in that position.

The firms that get this right won’t be the ones that moved fastest or the ones that banned everything. They’ll be the ones that give their people a safe way to say yes.

cta leading to safe gen AI usage policy ebook